Tech Support banner

Status
Not open for further replies.
1 - 3 of 3 Posts

·
Registered
Joined
·
1 Posts
Discussion Starter #1
Hi. A week ago, my computer got hijacked with the about:blank. I used several spyware removers, and was able to remove and reset my IE. The problem I now face is that whenever I restart my computer, a new hardware detected "Workstation NetLogon Service", and it's wanting to install on my computer.

I have read all I can about Workstation NetLogon Service. I do not have it installed on my computer, so I can't disable or stop it under Services Management. I believe it's connected to the about:blank hijack, because before then I didn't have this hardware detection. I can't delete the hardware because it's not actually installed.. I don't know what to do.
 

·
Registered
Joined
·
230 Posts
As you have read the Net logon service "Supports pass-through authentication of account logon events for computers in a domain."
This is usually installed by default on a Windows XP computer but
is set to manual start. If it were installed you could go to Start, Run, type
cmd and then type net stop netlogon and it would stop the service.

It maybe this virus and may have added the entry in the Registry.
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.armageddon.html

I would recommend making sure that Windows is up to date and running
the Trend Micro online virus scan if you have broadband.
http://housecall.trendmicro.com/
 

·
Registered User
Joined
·
1,438 Posts
Did you use coolwebshredder to treat your about:blank?
Download and run the removal tool
CWS 2.16 as of Sept,2005
Click on the download stand alone version of coolwebshredder
aumha.org/downloads/cwshredder.zip

Please download
Mcafee stinger multivirus removal tool
Install and run

Spybot search and destroy
Ad aware personal form Lavasoft
Install, update,run, check for problems , fix problems.
A Squared trojan remover
Download, install, update, scan and fix.

Hijackthis
Download, unzip and extract to a permanent folder of your creation such as C:\ProgramFiles\Hijackthis\Hijackthis.exe
Run and choose scan and save logfile. Copy the contents of the notepad window which opens and post it here.

I suspect that if you look in the hijackthis log there will be a 023 entry for your Net logon service

Hijackthis can be used to remove this after you kill the service in admin tools/ services ; but I advise you to post a long and have the admins move this to spyware / virus removal for an expert to review it first.
 
1 - 3 of 3 Posts
Status
Not open for further replies.
Top